It Compliance Analyst
CurrentScope, gather and evaluate evidence for PCI DSS information security self-assessments for Information Technology (IT) Security’s Governance, Risk & Compliance group. Coordinate and prepare self-assessment questionnaires (SAQs) for the company’s transaction authentication processing provider. Assess corporate cyber security infrastructure policies, procedures and practices, including network security, system configurations, data encryption (both in transit and stored), vulnerability management, secure software development, logical and physical access, user authentication, and system security, including anti-malware and security logging. Review and assess security at third-party service providers (TPSPs).Identify remediation actions and monitor gaps identified through security risk and controls assessments. Document policies and procedures for closing gaps in meeting security standards requirements. Assist with creation and operation of IT general controls, program processes, procedures and workflows. Prepare and maintain targeted risk assessment of payment card environment.Create and maintain third-party risk management response catalog for use in responding to customer/vendor security questionnaire requests. Track compliance processes such as remediation plans, exception/variance handling, audit requests, and recurring audit reviews to ensure timely completion. Work with key stakeholders, leadership, business units, and other internal and external constituents to evaluate and manage information security assessments.